{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T13:44:18Z","timestamp":1774964658297,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":136,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690224","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"2859-2873","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Samplable Anonymous Aggregation for Private Federated Data Analysis"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-5661-3541","authenticated-orcid":false,"given":"Kunal","family":"Talwar","sequence":"first","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4337-3774","authenticated-orcid":false,"given":"Shan","family":"Wang","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4231-6110","authenticated-orcid":false,"given":"Audra","family":"McMillan","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3904-759X","authenticated-orcid":false,"given":"Vitaly","family":"Feldman","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2169-3872","authenticated-orcid":false,"given":"Pansy","family":"Bansal","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7547-346X","authenticated-orcid":false,"given":"Bailey","family":"Basile","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-3977-1229","authenticated-orcid":false,"given":"Aine","family":"Cahill","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-9220-7366","authenticated-orcid":false,"given":"Yi Sheng","family":"Chan","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2234-8377","authenticated-orcid":false,"given":"Mike","family":"Chatzidakis","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-7613-701X","authenticated-orcid":false,"given":"Junye","family":"Chen","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6889-8561","authenticated-orcid":false,"given":"Oliver R. A.","family":"Chick","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9554-9523","authenticated-orcid":false,"given":"Mona","family":"Chitnis","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-5276-4099","authenticated-orcid":false,"given":"Suman","family":"Ganta","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1581-5724","authenticated-orcid":false,"given":"Yusuf","family":"Goren","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-9865-5178","authenticated-orcid":false,"given":"Filip","family":"Granqvist","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7437-2305","authenticated-orcid":false,"given":"Kristine","family":"Guo","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-0955-4194","authenticated-orcid":false,"given":"Frederic","family":"Jacobs","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8805-2210","authenticated-orcid":false,"given":"Omid","family":"Javidbakht","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-7092-579X","authenticated-orcid":false,"given":"Albert","family":"Liu","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8186-6510","authenticated-orcid":false,"given":"Richard","family":"Low","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-8408-1017","authenticated-orcid":false,"given":"Dan","family":"Mascenik","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-7348-4127","authenticated-orcid":false,"given":"Steve","family":"Myers","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3057-488X","authenticated-orcid":false,"given":"David","family":"Park","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0185-8275","authenticated-orcid":false,"given":"Wonhee","family":"Park","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-0283-4993","authenticated-orcid":false,"given":"Gianni","family":"Parsa","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-5451-5793","authenticated-orcid":false,"given":"Tommy","family":"Pauly","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8342-1048","authenticated-orcid":false,"given":"Christian","family":"Priebe","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1980-380X","authenticated-orcid":false,"given":"Rehan","family":"Rishi","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5273-6472","authenticated-orcid":false,"given":"Guy N.","family":"Rothblum","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5076-7299","authenticated-orcid":false,"given":"Congzheng","family":"Song","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4748-0045","authenticated-orcid":false,"given":"Linmao","family":"Song","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-4828-9458","authenticated-orcid":false,"given":"Karl","family":"Tarbe","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-6616-2808","authenticated-orcid":false,"given":"Sebastian","family":"Vogt","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-5167-4601","authenticated-orcid":false,"given":"Shundong","family":"Zhou","sequence":"additional","affiliation":[{"name":"Apple, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2972-4995","authenticated-orcid":false,"given":"Vojta","family":"Jina","sequence":"additional","affiliation":[{"name":"Researcher, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8806-3999","authenticated-orcid":false,"given":"Michael","family":"Scaria","sequence":"additional","affiliation":[{"name":"Base Power Company, Austin, TX, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2347-661X","authenticated-orcid":false,"given":"Luke","family":"Winstrom","sequence":"additional","affiliation":[{"name":"Researcher, Cupertino, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"URL https:\/\/developer.apple.com\/documentation\/devicecheck. Retreived","author":"DeviceCheck Framework Apple","year":"2023","unstructured":"Apple DeviceCheck Framework. URL https:\/\/developer.apple.com\/documentation\/devicecheck. Retreived June, 2023."},{"key":"e_1_3_2_1_2_1","volume-title":"URL https:\/\/developer.android.com\/google\/play\/integrity. Retreived","author":"Google Play","year":"2023","unstructured":"Google Play Integrity API. URL https:\/\/developer.android.com\/google\/play\/integrity. Retreived June, 2023."},{"key":"e_1_3_2_1_3_1","volume-title":"URL https:\/\/www.apple.com\/icloud\/docs\/iCloud_Private_Relay_Overview_Dec2021.pdf. Retreived","author":"Relay Overview Cloud Private","year":"2023","unstructured":"iCloud Private Relay Overview. URL https:\/\/www.apple.com\/icloud\/docs\/iCloud_Private_Relay_Overview_Dec2021.pdf. Retreived June, 2023."},{"key":"e_1_3_2_1_4_1","volume-title":"URL https:\/\/github.com\/tensorflow\/privacy. Retreived","author":"Privacy Tensorflow","year":"2023","unstructured":"Tensorflow Privacy. URL https:\/\/github.com\/tensorflow\/privacy. Retreived June, 2023."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-48965-0_40"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1162\/99608f92.529e3cb9"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-031--14791--3"},{"key":"e_1_3_2_1_9_1","volume-title":"Google covid-19 community mobility reports: Anonymization process description (version 1.1)","author":"Aktay A.","year":"2020","unstructured":"A. Aktay, S. Bavadekar, G. Cossoul, J. Davis, D. Desfontaines, A. Fabrikant, E. Gabrilovich, K. Gadepalli, B. Gipson, M. Guevara, C. Kamath, M. Kansal, A. Lange, C. Mandayam, A. Oplinger, C. Pluntke, T. Roessler, A. Schlosberg, T. Shekel, S. Vispute, M. Vu, G. Wellenius, B. Williams, and R. J. Wilson. Google covid-19 community mobility reports: Anonymization process description (version 1.1), 2020."},{"key":"e_1_3_2_1_10_1","volume-title":"Exposure notification privacy-preserving analytics (ENPA) white paper. https:\/\/covid19-static.cdn-apple.com\/applications\/covid19\/current\/static\/contact-tracing\/pdf\/ENPA_White_Paper.pdf","author":"Google Apple","year":"2021","unstructured":"Apple and Google. Exposure notification privacy-preserving analytics (ENPA) white paper. https:\/\/covid19-static.cdn-apple.com\/applications\/covid19\/current\/static\/contact-tracing\/pdf\/ENPA_White_Paper.pdf, 2021."},{"issue":"9","key":"e_1_3_2_1_11_1","article-title":"Learning with privacy at scale","volume":"1","author":"Privacy Team Apple's Differential","year":"2017","unstructured":"Apple's Differential Privacy Team. Learning with privacy at scale. Apple Machine Learning Journal, 1(9), 2017.","journal-title":"Apple Machine Learning Journal"},{"key":"e_1_3_2_1_12_1","volume-title":"Private vector mean estimation in the shuffle model: Optimal rates require many messages","author":"Asi H.","year":"2024","unstructured":"H. Asi, V. Feldman, J. Nelson, H. L. Nguyen, K. Talwar, and S. Zhou. Private vector mean estimation in the shuffle model: Optimal rates require many messages, 2024."},{"key":"e_1_3_2_1_13_1","series-title":"Proceedings of Machine Learning Research","first-page":"2938","volume-title":"Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics","author":"Bagdasaryan E.","year":"2020","unstructured":"E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov. How to backdoor federated learning. In S. Chiappa and R. Calandra, editors, Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics, volume 108 of Proceedings of Machine Learning Research, pages 2938--2948. PMLR, 2020."},{"key":"e_1_3_2_1_14_1","volume-title":"International Conference on Machine Learning","author":"Balle B.","year":"2018","unstructured":"B. Balle and Y.-X. Wang. Improving the gaussian mechanism for differential privacy: Analytical calibration and optimal denoising. In International Conference on Machine Learning, 2018."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-26951-7_22"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.726"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417242"},{"key":"e_1_3_2_1_18_1","volume-title":"Internet Engineering Task Force","author":"Barnes R.","year":"2023","unstructured":"R. Barnes, D. Cook, C. Patton, and P. Schoppmann. Verifiable Distributed Aggregation Functions. Internet-Draft draft-irtf-cfrg-vdaf-06, Internet Engineering Task Force, June 2023. URL https:\/\/datatracker.ietf.org\/doc\/draft-irtf-cfrg-vdaf\/06\/. Work in Progress."},{"key":"e_1_3_2_1_19_1","first-page":"49","volume-title":"Beyond differential privacy: Composition theorems and relational logic for f-divergences between probabilistic programs","author":"Barthe G.","year":"2013","unstructured":"G. Barthe and F. Olmedo. Beyond differential privacy: Composition theorems and relational logic for f-divergences between probabilistic programs. In F. V. Fomin, R. Freivalds, M. Kwiatkowska, and D. Peleg, editors, Automata, Languages, and Programming, pages 49--60, Berlin, Heidelberg, 2013. Springer Berlin Heidelberg."},{"key":"e_1_3_2_1_20_1","volume-title":"H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc","author":"Baruch G.","year":"2019","unstructured":"G. Baruch, M. Baruch, and Y. Goldberg. A little is enough: Circumventing defenses for distributed learning. In H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett, editors, Advances in Neural Information Processing Systems, volume 32. Curran Associates, Inc., 2019."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2014.56"},{"key":"e_1_3_2_1_22_1","volume-title":"Hierarchical organization of urban mobility and its connection with city livability. Nat Commun, 10(4817)","author":"Bassolas A.","year":"2019","unstructured":"A. Bassolas, H. Barbosa-Filho, B. Dickinson, X. Dotiwalla, P. Eastham, R. Gallotti, G. Ghoshal, B. Gipson, S. A. Hazarie, H. Kautz, O. Kucuktunc, A. Lieber, A. Sadilek, and J. J. Ramasco. Hierarchical organization of urban mobility and its connection with city livability. Nat Commun, 10(4817), 2019."},{"key":"e_1_3_2_1_23_1","volume-title":"Google covid-19 vaccination search insights: Anonymization process description","author":"Bavadekar S.","year":"2021","unstructured":"S. Bavadekar, A. Boulanger, J. Davis, D. Desfontaines, E. Gabrilovich, K. Gadepalli, B. Ghazi, T. Griffith, J. Gupta, C. Kamath, D. Kraft, R. Kumar, A. Kumok, Y. Mayer, P. Manurangsi, A. Patankar, I. M. Perera, C. Scott, T. Shekel, B. Miller, K. Smith, C. Stanton, M. Sun, M. Young, and G. Wellenius. Google covid-19 vaccination search insights: Anonymization process description, 2021."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"J. Bell K. A. Bonawitz A. Gasc\u00f3n T. Lepoint and M. Raykova. Secure single-server aggregation with (poly)logarithmic overhead. Cryptology ePrint Archive Report 2020\/704 2020. https:\/\/eprint.iacr.org\/2020\/704.","DOI":"10.1145\/3372297.3417885"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559383"},{"key":"e_1_3_2_1_26_1","volume-title":"Paper 2023\/320","author":"Benhamouda F.","year":"2023","unstructured":"F. Benhamouda, M. Raykova, and K. Seth. Anonymous counting tokens. Cryptology ePrint Archive, Paper 2023\/320, 2023. URL https:\/\/eprint.iacr.org\/2023\/320. https:\/\/eprint.iacr.org\/2023\/320."},{"key":"e_1_3_2_1_27_1","series-title":"Proceedings of Machine Learning Research","first-page":"560","volume-title":"Proceedings of the 35th International Conference on Machine Learning","author":"Bernstein J.","year":"2018","unstructured":"J. Bernstein, Y.-X. Wang, K. Azizzadenesheli, and A. Anandkumar. signSGD: Compressed optimisation for non-convex problems. In J. Dy and A. Krause, editors, Proceedings of the 35th International Conference on Machine Learning, volume 80 of Proceedings of Machine Learning Research, pages 560--569. PMLR, 10--15 Jul 2018."},{"key":"e_1_3_2_1_28_1","series-title":"Proceedings of Machine Learning Research","first-page":"634","volume-title":"Proceedings of the 36th International Conference on Machine Learning","author":"Bhagoji A. N.","year":"2019","unstructured":"A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo. Analyzing federated learning through an adversarial lens. In K. Chaudhuri and R. Salakhutdinov, editors, Proceedings of the 36th International Conference on Machine Learning, volume 97 of Proceedings of Machine Learning Research, pages 634--643. PMLR, 2019."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132769"},{"key":"e_1_3_2_1_30_1","volume-title":"Advances in Neural Information Processing Systems","author":"Blanchard P.","year":"2017","unstructured":"P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer. Machine learning with adversaries: Byzantine tolerant gradient descent. In I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett, editors, Advances in Neural Information Processing Systems, volume 30. Curran Associates, Inc., 2017."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1918257117"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00020"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00023"},{"key":"e_1_3_2_1_34_1","first-page":"135","volume-title":"Proceedings on Privacy Enhancing Technologies","volume":"2016","author":"Bogdanov D.","unstructured":"D. Bogdanov, L. Kamm, B. Kubo, R. Rebane, V. Sokk, and R. Talviste. Students and taxes: a privacy-preserving study using secure computation. In Proceedings on Privacy Enhancing Technologies, volume 2016, pages 117?-135."},{"key":"e_1_3_2_1_35_1","volume-title":"Secure Multiparty Computation Goes Live, page 325--343","author":"Bogetoft P.","year":"2009","unstructured":"P. Bogetoft, D. L. Christensen, I. Damg\u00e5rd, M. Geisler, T. Jakobsen, M. Kr\u00f8igaard, J. D. Nielsen, J. B. Nielsen, K. Nielsen, J. Pagter, M. Schwartzbach, and T. Toft. Secure Multiparty Computation Goes Live, page 325--343. Springer-Verlag, Berlin, Heidelberg, 2009. ISBN 9783642035487."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-26954-8_3"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00048"},{"key":"e_1_3_2_1_39_1","volume-title":"Paper 2023\/1012","author":"Boneh D.","year":"2023","unstructured":"D. Boneh, E. Boyle, H. Corrigan-Gibbs, N. Gilboa, and Y. Ishai. Arithmetic sketching. Cryptology ePrint Archive, Paper 2023\/1012, 2023. URL https:\/\/eprint.iacr.org\/2023\/1012. https:\/\/eprint.iacr.org\/2023\/1012."},{"key":"e_1_3_2_1_40_1","first-page":"991","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Bulck J. V.","year":"2018","unstructured":"J. V. Bulck, M. Minkin, O. Weisse, D. Genkin, B. Kasikci, F. Piessens, M. Silberstein, T. F. Wenisch, Y. Yarom, and R. Strackx. Foreshadow: Extracting the keys to the intel SGX kingdom with transient Out-of-Order execution. In 27th USENIX Security Symposium (USENIX Security 18), page 991--1008, Baltimore, MD, 2018. USENIX Association. ISBN 978--1--939133-04--5."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53641-4_24"},{"key":"e_1_3_2_1_42_1","volume-title":"The discrete gaussian for differential privacy","author":"Canonne C. L.","year":"2020","unstructured":"C. L. Canonne, G. Kamath, and T. Steinke. The discrete gaussian for differential privacy. 2020."},{"key":"e_1_3_2_1_43_1","first-page":"267","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium, SEC'19","author":"Carlini N.","year":"2019","unstructured":"N. Carlini, C. Liu, U. Erlingsson, J. Kos, and D. Song. The secret sharer: Evaluating and testing unintended memorization in neural networks. In Proceedings of the 28th USENIX Conference on Security Symposium, SEC'19, page 267--284, USA, 2019. USENIX Association. ISBN 9781939133069."},{"key":"e_1_3_2_1_44_1","volume-title":"USENIX Security Symposium, 2021","author":"Carlini N.","year":"2012","unstructured":"N. Carlini, F. Tram\u00e8r, E. Wallace, M. Jagielski, A. Herbert-Voss, K. Lee, A. Roberts, T. Brown, D. Song, U. Erlingsson, A. Oprea, and C. Raffel. Extracting training data from large language models. In USENIX Security Symposium, 2021. URL https:\/\/arxiv.org\/abs\/2012.07805."},{"key":"e_1_3_2_1_45_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Carlini N.","year":"2023","unstructured":"N. Carlini, D. Ippolito, M. Jagielski, K. Lee, F. Tram\u00e8r, and C. Zhang. Quantifying memorization across neural language models. In International Conference on Learning Representations (ICLR), 2023. URL https:\/\/arxiv.org\/abs\/2202.07646."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML59370.2024.00032"},{"issue":"29","key":"e_1_3_2_1_47_1","first-page":"1069","article-title":"Differentially private empirical risk minimization","volume":"12","author":"Chaudhuri K.","year":"2011","unstructured":"K. Chaudhuri, C. Monteleoni, and A. D. Sarwate. Differentially private empirical risk minimization. Journal of Machine Learning Research, 12(29):1069--1109, 2011. URL http:\/\/jmlr.org\/papers\/v12\/chaudhuri11a.html.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/358549.358563"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17653-2_13"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.754"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1038\/nbt.4108"},{"key":"e_1_3_2_1_52_1","first-page":"1420","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Cormode G.","year":"2022","unstructured":"G. Cormode and A. Bharadwaj. Sample-and-threshold differential privacy: Histograms and applications. In International Conference on Artificial Intelligence and Statistics, pages 1420--1431. PMLR, 2022."},{"key":"e_1_3_2_1_53_1","first-page":"259","volume-title":"14th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2017","author":"Corrigan-Gibbs H.","year":"2017","unstructured":"H. Corrigan-Gibbs and D. Boneh. Prio: Private, robust, and scalable computation of aggregate statistics. In A. Akella and J. Howell, editors, 14th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2017, Boston, MA, USA, March 27--29, 2017, pages 259--282. USENIX Association, 2017."},{"key":"e_1_3_2_1_54_1","volume-title":"Retreived","author":"C.-T. D. C.","year":"2023","unstructured":"C.-T. D. C. (CTDC). Global victim-perpetrator synthetic dataset, 2022. URL https:\/\/www.ctdatacollaborative.org\/global-victim-perpetrator-synthetic-dataset. Retreived June, 2023."},{"key":"e_1_3_2_1_55_1","first-page":"180","volume-title":"Proceedings on Privacy Enhancing Technologies","volume":"2018","author":"Davidson A.","unstructured":"A. Davidson, I. Goldberg, N. Sullivan, G. Tankersley, and F. Valsorda. Privacy pass: Bypassing internet challenges anonymously. In Proceedings on Privacy Enhancing Technologies, volume 2018, pages 164?-180."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-06944-4_6"},{"key":"e_1_3_2_1_57_1","volume-title":"Scram: A Platform for Securely Measuring Cyber Risk. Harvard Data Science Review, 2(3), sep 16","author":"de Castro L.","year":"2020","unstructured":"L. de Castro, A. W. Lo, T. Reynolds, F. Susan, V. Vaikuntanathan, D. Weitzner, and N. Zhang. Scram: A Platform for Securely Measuring Cyber Risk. Harvard Data Science Review, 2(3), sep 16 2020. https:\/\/hdsr.mitpress.mit.edu\/pub\/gylaxji4."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.5555\/3294996.3295115"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.21236\/ADA465464"},{"key":"e_1_3_2_1_60_1","volume-title":"Collaborative privacy-preserving analysis of oncological data. https:\/\/dualitytech.com\/blog\/collaborative-analysis-oncological-data\/. Retreived","author":"Duchin Z.","year":"2023","unstructured":"Z. Duchin, M. Blatt, and Y. Polyakov. Collaborative privacy-preserving analysis of oncological data. https:\/\/dualitytech.com\/blog\/collaborative-analysis-oncological-data\/. Retreived July 2023."},{"key":"e_1_3_2_1_61_1","volume-title":"The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci., 9(3--4):211--407","author":"Dwork C.","year":"2014","unstructured":"C. Dwork and A. Roth. The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci., 9(3--4):211--407, 2014."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.12"},{"key":"e_1_3_2_1_65_1","volume-title":"Confidential federated computations","author":"Eichner H.","year":"2024","unstructured":"H. Eichner, D. Ramage, K. Bonawitz, D. Huba, T. Santoro, B. McLarnon, T. V. Overveldt, N. Fallen, P. Kairouz, A. Cheu, K. Daly, A. Gascon, M. Gruteser, and B. McMahan. Confidential federated computations, 2024."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611975482.151"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384290"},{"key":"e_1_3_2_1_69_1","first-page":"2881","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Feldman V.","year":"2020","unstructured":"V. Feldman and C. Zhang. What neural networks memorize and why: Discovering the long tail via influence estimation. In H. Larochelle, M. Ranzato, R. Hadsell, M. Balcan, and H. Lin, editors, Advances in Neural Information Processing Systems, volume 33, pages 2881--2891. Curran Associates, Inc., 2020."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS52979.2021.00096"},{"key":"e_1_3_2_1_71_1","volume-title":"Retreived","author":"Foote A.","year":"2023","unstructured":"A. Foote, J. K. Hahn, S. Tibbets, and L. Warren. \"post-secondary employment outcomes, 2023. URL https:\/\/lehd.ces.census.gov\/doc\/PSEOTechnicalDocumentation.pdf. Retreived June, 2023."},{"key":"e_1_3_2_1_72_1","volume-title":"International Conference on Learning Representations","author":"Fowl L. H.","year":"2022","unstructured":"L. H. Fowl, J. Geiping, W. Czaja, M. Goldblum, and T. Goldstein. Robbing the fed: Directly obtaining private data in federated learning with modified models. In International Conference on Learning Representations, 2022. URL https:\/\/openreview.net\/forum?id=fwzUgo0FM9v."},{"key":"e_1_3_2_1_73_1","first-page":"250","volume-title":"Proceedings on Privacy Enhancing Technologies","volume":"2017","author":"Froelicher D.","unstructured":"D. Froelicher, P. Egger, J. S. Sousa, J. L. Raisaro, Z. Huang, C. Mouchet, B. Ford, and J.-P. Hubaux. UnLynx: A decentralized system for privacy-conscious data sharing. In Proceedings on Privacy Enhancing Technologies, volume 2017, pages 232?-250."},{"key":"e_1_3_2_1_74_1","volume-title":"Truly privacy-preserving federated analytics for precision medicine with multiparty homomorphic encryption. Nat Commun., 12(1)","author":"Froelicher D.","year":"2021","unstructured":"D. Froelicher, J. R. Troncoso-Pastoriza, J. L. Raisaro, M. A. Cuendet, J. S. Sousa, H. Cho, B. Berger, J. Fellay, and J.-P. Hubaux. Truly privacy-preserving federated analytics for precision medicine with multiparty homomorphic encryption. Nat Commun., 12(1), 2021."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.5555\/3495724.3497145"},{"key":"e_1_3_2_1_76_1","volume-title":"Exposure notifications privacy analytics","author":"Geoghegan T.","year":"2022","unstructured":"T. Geoghegan and M. Raykova. Exposure notifications privacy analytics, 2022. IACR Real World Crypto (RWC) talk."},{"key":"e_1_3_2_1_77_1","volume-title":"Internet Engineering Task Force","author":"Geoghegan T.","year":"2023","unstructured":"T. Geoghegan, C. Patton, E. Rescorla, and C. A. Wood. Distributed Aggregation Protocol for Privacy Preserving Measurement. Internet-Draft draft-ietf-ppm-dap-04, Internet Engineering Task Force, Mar. 2023. URL https:\/\/datatracker.ietf.org\/doc\/draft-ietf-ppm-dap\/04\/. Work in Progress."},{"key":"e_1_3_2_1_78_1","first-page":"798","volume-title":"Proceedings, Part II","author":"Ghazi B.","year":"2020","unstructured":"B. Ghazi, P. Manurangsi, R. Pagh, and A. Velingker. Private aggregation from fewer anonymous messages. In Advances in Cryptology - EUROCRYPT 2020 - 39th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Proceedings, Part II, pages 798--827, 2020."},{"key":"e_1_3_2_1_79_1","first-page":"3692","volume-title":"Proceedings of the 38th International Conference on Machine Learning, ICML","author":"Ghazi B.","year":"2021","unstructured":"B. Ghazi, R. Kumar, P. Manurangsi, R. Pagh, and A. Sinha. Differentially private aggregation in the shuffle model: Almost central accuracy in almost a single message. In Proceedings of the 38th International Conference on Machine Learning, ICML, pages 3692--3701, 2021."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/293411.293443"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2944"},{"key":"e_1_3_2_1_82_1","volume-title":"Testing privacy-preserving telemetry with prio. https:\/\/hacks.mozilla.org\/2018\/10\/testing-privacy-preserving-telemetry-with-prio\/","author":"Helmer R.","year":"2018","unstructured":"R. Helmer, A. Miyaguchi, and E. Rescorla. Testing privacy-preserving telemetry with prio. https:\/\/hacks.mozilla.org\/2018\/10\/testing-privacy-preserving-telemetry-with-prio\/, 2018."},{"key":"e_1_3_2_1_83_1","volume-title":"Internet Engineering Task Force","author":"Hendrickson S.","year":"2023","unstructured":"S. Hendrickson, J. Iyengar, T. Pauly, S. Valdez, and C. A. Wood. Rate-Limited Token Issuance Protocol. Internet-Draft draft-ietf-privacypass-rate-limit-tokens-01, Internet Engineering Task Force, Mar. 2023. URL https:\/\/datatracker.ietf.org\/doc\/draft-ietf-privacypass-rate-limit-tokens\/01\/. Work in Progress."},{"key":"e_1_3_2_1_84_1","first-page":"814","volume-title":"Papaya: Practical, private, and scalable federated learning","author":"Huba D.","year":"2022","unstructured":"D. Huba, J. Nguyen, K. Malik, R. Zhu, M. Rabbat, A. Yousefpour, C.-J. Wu, H. Zhan, P. Ustinov, H. Srinivas, K. Wang, A. Shoumikhin, J. Min, and M. Malek. Papaya: Practical, private, and scalable federated learning. In D. Marculescu, Y. Chi, and C. Wu, editors, Proceedings of Machine Learning and Systems, volume 4, pages 814--832, 2022."},{"key":"e_1_3_2_1_85_1","volume-title":"URL https:\/\/github.com\/divviup\/libprio-rs. Retreived","author":"ISRG.","year":"2023","unstructured":"ISRG. Divviup libprio rust, 2023. URL https:\/\/github.com\/divviup\/libprio-rs. Retreived June 2023."},{"key":"e_1_3_2_1_86_1","unstructured":"J. Iyengar and J. Foot. Private access tokens: stepping into the privacy-respecting captcha-less future we were promised. URL https:\/\/www.fastly.com\/blog\/private-access-tokens-stepping-into-the-privacy-respecting-captcha-less. Blog Post 2022."},{"key":"e_1_3_2_1_87_1","volume-title":"Elephants do not forget: Differential privacy with state continuity for privacy budget","author":"Jin J.","year":"2024","unstructured":"J. Jin, C. Chuengsatiansup, T. Murray, B. I. P. Rubinstein, Y. Yarom, and O. Ohrimenko. Elephants do not forget: Differential privacy with state continuity for privacy budget, 2024."},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1093\/bioinformatics\/btt066"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2008.27"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--56784--2_11"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2016.027"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2008.4497436"},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.7910\/DVN\/TDOAPG"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_2_1_96_1","volume-title":"R\u00e9nyi differential privacy of the sampled gaussian mechanism. ArXiv, abs\/1908.10530","author":"Mironov I.","year":"2019","unstructured":"I. Mironov, K. Talwar, and L. Zhang. R\u00e9nyi differential privacy of the sampled gaussian mechanism. ArXiv, abs\/1908.10530, 2019."},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_98_1","first-page":"1415","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Nguyen T. D.","year":"2022","unstructured":"T. D. Nguyen, P. Rieger, H. Chen, H. Yalame, H. M\u00f6llering, H. Fereidooni, S. Marchal, M. Miettinen, A. Mirhoseini, S. Zeitouni, F. Koushanfar, A.-R. Sadeghi, and T. Schneider. FLAME: Taming backdoors in federated learning. In 31st USENIX Security Symposium (USENIX Security 22), pages 1415--1432, Boston, MA, 2022. USENIX Association. ISBN 978--1--939133--31--1."},{"key":"e_1_3_2_1_99_1","volume-title":"Applying energy differential privacy to enable measurement of the ohmconnect virtual power plant. URL https:\/\/edp.recurve.com. Retreived","author":"Par\u00e9 M.","year":"2023","unstructured":"M. Par\u00e9, M. Teehan, S. Suffian, J. Glass, A. Scheer, M. Young, and M. Golden. Applying energy differential privacy to enable measurement of the ohmconnect virtual power plant. URL https:\/\/edp.recurve.com. Retreived June 2023."},{"key":"e_1_3_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560557"},{"key":"e_1_3_2_1_101_1","volume-title":"Federated evaluation and tuning for on-device personalization: System design and applications","author":"Paulik M.","year":"2022","unstructured":"M. Paulik, M. Seigel, H. Mason, D. Telaar, J. Kluivers, R. van Dalen, C. W. Lau, L. Carlson, F. Granqvist, C. Vandevelde, S. Agarwal, J. Freudiger, A. Byde, A. Bhowmick, G. Kapoor, S. Beaumont, \u00c1ine Cahill, D. Hughes, O. Javidbakht, F. Dong, R. Rishi, and S. Hung. Federated evaluation and tuning for on-device personalization: System design and applications, 2022. URL https:\/\/arxiv.org\/pdf\/2102.08503.pdf."},{"key":"e_1_3_2_1_102_1","volume-title":"s. broadband coverage data set: A differentially private data release","author":"Pereira M.","year":"2021","unstructured":"M. Pereira, A. Kim, J. Allen, K. White, J. L. Ferres, and R. Dodhia. U.s. broadband coverage data set: A differentially private data release, 2021."},{"key":"e_1_3_2_1_103_1","volume-title":"ELSA: secure aggregation for federated learning with malicious actors. IACR Cryptol. ePrint Arch., page 1695","author":"Rathee M.","year":"2022","unstructured":"M. Rathee, C. Shen, S. Wagh, and R. A. Popa. ELSA: secure aggregation for federated learning with malicious actors. IACR Cryptol. ePrint Arch., page 1695, 2022. URL https:\/\/eprint.iacr.org\/2022\/1695."},{"key":"e_1_3_2_1_104_1","volume-title":"A members first approach to enabling linkedin?s labor market insights at scale","author":"Rogers R.","year":"2020","unstructured":"R. Rogers, A. R. Cardoso, K. Mancuhan, A. Kaura, N. Gahlawat, N. Jain, P. Ko, and P. Ahammad. A members first approach to enabling linkedin?s labor market insights at scale, 2020."},{"key":"e_1_3_2_1_105_1","volume-title":"Linkedin's audience engagements api: A privacy preserving data analytics system at scale","author":"Rogers R.","year":"2020","unstructured":"R. Rogers, S. Subramaniam, S. Peng, D. Durfee, S. Lee, S. K. Kancha, S. Sahay, and P. Ahammad. Linkedin's audience engagements api: A privacy preserving data analytics system at scale, 2020."},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359660"},{"key":"e_1_3_2_1_107_1","first-page":"1065","volume-title":"14th USENIX Symposium on Operating Systems Design and Implementation (OSDI 20)","author":"Roth E.","year":"2020","unstructured":"E. Roth, H. Zhang, A. Haeberlen, and B. C. Pierce. Orchard: Differentially private analytics at scale. In 14th USENIX Symposium on Operating Systems Design and Implementation (OSDI 20), pages 1065--1081. USENIX Association, Nov. 2020. ISBN 978--1--939133--19--9."},{"key":"e_1_3_2_1_108_1","volume-title":"Pine: Efficient verification of a euclidean norm bound of a secret-shared vector. Usenix Security","author":"Rothblum G.","year":"2024","unstructured":"G. Rothblum, E. Omri, J. Chen, and K. Talwar. Pine: Efficient verification of a euclidean norm bound of a secret-shared vector. Usenix Security 2024. To Appear."},{"key":"e_1_3_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3380596"},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"crossref","unstructured":"D. Schinazi. Proxying UDP in HTTP. RFC 9298 Aug. 2022. URL https:\/\/www.rfc-editor.org\/info\/rfc9298.","DOI":"10.17487\/RFC9298"},{"key":"e_1_3_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"e_1_3_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-031--18283--9_9"},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAIT.2021.3054610"},{"key":"e_1_3_2_1_115_1","volume-title":"Can you really backdoor federated learning? CoRR, abs\/1911.07963","author":"Sun Z.","year":"2019","unstructured":"Z. Sun, P. Kairouz, A. T. Suresh, and H. B. McMahan. Can you really backdoor federated learning? CoRR, abs\/1911.07963, 2019. URL http:\/\/arxiv.org\/abs\/1911.07963."},{"key":"e_1_3_2_1_116_1","first-page":"1","volume-title":"3rd Symposium on Foundations of Responsible Computing, FORC 2022","volume":"218","author":"Talwar K.","year":"2022","unstructured":"K. Talwar. Differential secrecy for distributed data and applications to robust differentially secure vector summation. In L. E. Celis, editor, 3rd Symposium on Foundations of Responsible Computing, FORC 2022, June 6--8, 2022, Cambridge, MA, USA, volume 218 of LIPIcs, pages 7:1--7:16. Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik, 2022."},{"key":"e_1_3_2_1_117_1","volume-title":"Samplable anonymous aggregation for private federated data analytics","author":"Talwar K.","year":"2024","unstructured":"K. Talwar, S. Wang, A. McMillan, V. Jina, V. Feldman, P. Bansal, B. Basile, A. Cahill, Y. S. Chan, M. Chatzidakis, J. Chen, O. Chick, M. Chitnis, S. Ganta, Y. Goren, F. Granqvist, K. Guo, F. Jacobs, O. Javidbakht, A. Liu, R. Low, D. Mascenik, S. Myers, D. Park, W. Park, G. Parsa, T. Pauly, C. Priebe, R. Rishi, G. Rothblum, M. Scaria, L. Song, C. Song, K. Tarbe, S. Vogt, L. Winstrom, and S. Zhou. Samplable anonymous aggregation for private federated data analytics, 2024. URL https:\/\/arxiv.org\/abs\/2307.15017."},{"key":"e_1_3_2_1_118_1","volume-title":"Blog Post","author":"Tatoris R.","year":"2022","unstructured":"R. Tatoris and M. Guerreiro. Private access tokens: eliminating captchas on iphones and macs with open standards. URL https:\/\/blog.cloudflare.com\/eliminating-captchas-on-iphones-and-macs-using-new-standard\/. Blog Post, 2022."},{"key":"e_1_3_2_1_119_1","volume-title":"Internet Engineering Task Force","author":"Thomson M.","year":"2023","unstructured":"M. Thomson and C. A. Wood. Oblivious HTTP. Internet-Draft draft-ietf-ohai-ohttp-08, Internet Engineering Task Force, Mar. 2023. URL https:\/\/ietf-wg-ohai.github.io\/oblivious-http\/draft-ietf-ohai-ohttp.html. Work in Progress."},{"key":"e_1_3_2_1_120_1","volume-title":"Rigorous approaches to data privacy","author":"Ullman J.","year":"2017","unstructured":"J. Ullman. Lecture notes for cs788: Rigorous approaches to data privacy, 2017."},{"key":"e_1_3_2_1_121_1","first-page":"16070","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Wang H.","year":"2020","unstructured":"H. Wang, K. Sreenivasan, S. Rajput, H. Vishwakarma, S. Agarwal, J.-y. Sohn, K. Lee, and D. Papailiopoulos. Attack of the tails: Yes, you really can backdoor federated learning. In H. Larochelle, M. Ranzato, R. Hadsell, M. Balcan, and H. Lin, editors, Advances in Neural Information Processing Systems, volume 33, pages 16070--16084. Curran Associates, Inc., 2020."},{"key":"e_1_3_2_1_122_1","volume-title":"Invariant aggregator for defending against federated backdoor attacks","author":"Wang X.","year":"2023","unstructured":"X. Wang, D. Dimitriadis, S. Koyejo, and S. Tople. Invariant aggregator for defending against federated backdoor attacks, 2023."},{"key":"e_1_3_2_1_123_1","first-page":"183","article-title":"Learning with differential privacy: Stability, learnability and the sufficiency and necessity of ERM principle","volume":"17","author":"Wang Y.-X.","year":"2016","unstructured":"Y.-X. Wang, J. Lei, and S. E. Fienberg. Learning with differential privacy: Stability, learnability and the sufficiency and necessity of ERM principle. J. Mach. Learn. Res., 17:183:1--183:40, 2016.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.723"},{"key":"e_1_3_2_1_125_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"e_1_3_2_1_126_1","series-title":"Proceedings of Machine Learning Research","first-page":"23668","volume-title":"Proceedings of the 39th International Conference on Machine Learning","author":"Wen Y.","year":"2022","unstructured":"Y. Wen, J. A. Geiping, L. Fowl, M. Goldblum, and T. Goldstein. Fishing for user data in large-batch federated learning via gradient magnification. In K. Chaudhuri, S. Jegelka, L. Song, C. Szepesvari, G. Niu, and S. Sabato, editors, Proceedings of the 39th International Conference on Machine Learning, volume 162 of Proceedings of Machine Learning Research, pages 23668--23684. PMLR, 17--23 Jul 2022. URL https:\/\/proceedings.mlr.press\/v162\/wen22a.html."},{"key":"e_1_3_2_1_127_1","volume-title":"European Symposium on System Security (EuroSec)","author":"Wolinsky D.","year":"2012","unstructured":"D. Wolinsky, H. Corrigan-Gibbs, B. Ford, and A. Johnson. Scalable anonymous group communication in the anytrust model. In European Symposium on System Security (EuroSec), 2012."},{"key":"e_1_3_2_1_128_1","first-page":"16913","volume-title":"Advances in Neural Information Processing Systems","volume":"34","author":"Wu D.","year":"2021","unstructured":"D. Wu and Y. Wang. Adversarial neuron pruning purifies backdoored deep models. In M. Ranzato, A. Beygelzimer, Y. Dauphin, P. Liang, and J. W. Vaughan, editors, Advances in Neural Information Processing Systems, volume 34, pages 16913--16925. Curran Associates, Inc., 2021."},{"key":"e_1_3_2_1_129_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-46147-8_13"},{"key":"e_1_3_2_1_130_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-industry.60"},{"key":"e_1_3_2_1_131_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"e_1_3_2_1_132_1","volume-title":"PriML Workshop at NeurIPS.","author":"Yousefpour A.","unstructured":"A. Yousefpour, I. Shilov, A. Sablayrolles, D. Testuggine, K. Prasad, M. Malek, J. Nguyen, S. Ghosh, A. Bharadwaj, J. Zhao, et al. Opacus: User-friendly differential privacy library in PyTorch. arXiv preprint arXiv:2109.12298, 2021. PriML Workshop at NeurIPS."},{"key":"e_1_3_2_1_133_1","volume-title":"Private federated learning in gboard","author":"Zhang Y.","year":"2023","unstructured":"Y. Zhang, D. Ramage, Z. Xu, Y. Zhang, S. Zhai, and P. Kairouz. Private federated learning in gboard, 2023."},{"key":"e_1_3_2_1_134_1","volume-title":"idlg: Improved deep leakage from gradients. CoRR, abs\/2001.02610","author":"Zhao B.","year":"2020","unstructured":"B. Zhao, K. R. Mopuri, and H. Bilen. idlg: Improved deep leakage from gradients. CoRR, abs\/2001.02610, 2020. URL http:\/\/arxiv.org\/abs\/2001.02610."},{"key":"e_1_3_2_1_135_1","volume-title":"H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc","author":"Zhu L.","year":"2019","unstructured":"L. Zhu, Z. Liu, and S. Han. Deep leakage from gradients. In H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett, editors, Advances in Neural Information Processing Systems, volume 32. Curran Associates, Inc., 2019. URL https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2019\/file\/60a6c4002cc7b29142def8871531281a-Paper.pdf."},{"key":"e_1_3_2_1_136_1","first-page":"3837","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Zhu W.","year":"2020","unstructured":"W. Zhu, P. Kairouz, B. McMahan, H. Sun, and W. Li. Federated heavy hitters discovery with differential privacy. In International Conference on Artificial Intelligence and Statistics, pages 3837--3847. PMLR, 2020."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690224","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690224","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:10:11Z","timestamp":1755843011000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690224"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":136,"alternative-id":["10.1145\/3658644.3690224","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690224","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}